Description
Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.14.0, stanza.resources.common.unzip in stanza/resources/common.py passes downloaded model and resource archives to zipfile.ZipFile.extractall without validating member paths, and the vulnerable extraction path is reachable through stanza.download and stanza.install_corenlp. A malicious archive containing parent-directory traversal entries can write outside the intended model directory, allowing files writable by the Stanza process to be overwritten and potentially enabling code execution through modified shell configuration, SSH authorization data, Python packages, or executable scripts. This issue is fixed in version 1.14.0.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary file overwrite via zip slip in model extraction, potentially leading to remote code execution
Action: Patch Now
AI Analysis

Impact

Stanza, a Stanford NLP Python library, contained a zip slip flaw in the function that extracts downloaded model archives. The vulnerability arises because the extraction routine passes archive members directly to zipfile.ZipFile.extractall without validating their paths. A malicious archive that includes parent-directory traversal entries can therefore write files outside the intended model directory, overwriting files that are writable by the Stanza process. Such overwrites can be leveraged to modify shell configuration, SSH authorization data, Python packages, or executable scripts, thereby enabling arbitrary code execution.

Affected Systems

The affected product is Stanford NLP Stanza. Versions earlier than 1.14.0 are susceptible, as the cracking extraction logic is present only in those releases.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity, and the EPSS score of less than 1% points to a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through the Stanza download or installation process; an adversary could supply a crafted archive via the internet or a malicious internal source. If executed, the exploit would allow overwrite of privileged files and potentially remote code execution. This risk is elevated if the Stanza process runs with elevated permissions or in a multi-user environment.

Generated by OpenCVE AI on September 18, 2026 at 01:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Stanza to version 1.14.0 or later to apply the fix that validates extraction paths
  • Restrict the source of model archives to trusted, signed repositories to prevent delivery of malicious content
  • Implement path validation or use the patched extraction function in environments where upgrading is not yet possible, ensuring that no traversal paths can reach outside the intended model directory

Generated by OpenCVE AI on September 18, 2026 at 01:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Stanfordnlp
Stanfordnlp stanza
Vendors & Products Stanfordnlp
Stanfordnlp stanza

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.14.0, stanza.resources.common.unzip in stanza/resources/common.py passes downloaded model and resource archives to zipfile.ZipFile.extractall without validating member paths, and the vulnerable extraction path is reachable through stanza.download and stanza.install_corenlp. A malicious archive containing parent-directory traversal entries can write outside the intended model directory, allowing files writable by the Stanza process to be overwritten and potentially enabling code execution through modified shell configuration, SSH authorization data, Python packages, or executable scripts. This issue is fixed in version 1.14.0.
Title Stanza: Zip Slip Path Traversal in Model/Resource Extraction
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Stanfordnlp Stanza
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T17:28:08.634Z

Reserved: 2026-07-07T19:41:00.004Z

Link: CVE-2026-59974

cve-icon Vulnrichment

Updated: 2026-09-16T17:27:50.165Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T17:17:28.877

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-59974

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:30:03Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')